Skip to content
DEFLECTO
Acceptable Use Policy

What you may not put behind this network.

DEFLECTO absorbs attacks. It is not a place to launch them from, and it is not cover for a service whose own product is attacking other people. This policy sets out what is prohibited, what happens when it is found, and the narrow room reserved for good-faith security research.

Last updated
Status
Draft
Applies to
DEFLECTO WAF and reverse proxy
Draft, company being formed

DEFLECTO LLC is in the process of being incorporated and is not registered yet, so there is not currently a legal person able to enter into this agreement. Registration is underway and expected shortly. Until it completes, this document is published for comment and is not binding on anyone, it has not been reviewed by counsel, and every value shown in a red box is a fact that will be filled in once the company exists.

Most of this is what you would expect: no illegal content, no malware, no phishing, no spam operations. Two clauses are here because they are specific to what we sell. Clause 4 exists because a DDoS mitigation provider fronting a booter panel is a contradiction we will not host. Clause 5 exists because our billing only counts forwarded requests, and a metering rule that generous only works if nobody games it.

1Scope

This policy applies to every account, every Protected Property, and everyone using the Service through you, including your own end users and your customers if you resell. It forms part of the Terms of Service, and a breach of this policy is a breach of that agreement.

The lists below are illustrative, not exhaustive. Conduct that is plainly within the spirit of a prohibition is prohibited, and we will not entertain an argument that turns on a technicality of wording.

We do not monitor customer content proactively and we have no general obligation to do so. We act on reports, on evidence from our own network, and on lawful orders.

2Prohibited content

You may not use the Service to host, serve, distribute, link to or front:

  • Child sexual abuse material. There is no notice period, no appeal and no discussion. The account is terminated on discovery and reported to the appropriate authority and to the relevant hotline.
  • Content that is unlawful where it is served or where we operate, including material that incites violence or terrorism, or that constitutes unlawful harassment or a credible threat.
  • Malware, ransomware, exploit kits, cryptominers deployed without the device owner's knowledge, or command and control endpoints for any of them.
  • Phishing pages, fake login portals, brand impersonation, and infrastructure supporting a fraud or social engineering campaign.
  • Material infringing copyright, trademark or other intellectual property rights, and repeat infringement after a valid notice.
  • Counterfeit goods, stolen credentials, stolen payment data, or marketplaces trading in any of them.
  • Content published in breach of another person's privacy, including doxxing, non-consensual intimate imagery, and databases of personal data obtained from a breach.

3Prohibited network conduct

You may not use the Service, or anything reachable through it, to:

  • Launch, participate in, coordinate or relay a denial of service attack of any kind, volumetric or application layer.
  • Scan, enumerate, fingerprint or probe hosts, ports or services you do not own and are not authorised in writing to test.
  • Attempt to gain unauthorised access to any system, account or network, or to escalate privileges on one.
  • Intercept, sniff or tamper with traffic that is not yours.
  • Send unsolicited bulk email, run a spam operation, or host the landing pages, redirectors or list infrastructure for one.
  • Circumvent another network's access controls, rate limits, geo restrictions, paywalls or bot defences, or operate a scraping service designed to do so at scale.
  • Use the Service as an open proxy, an anonymising relay, or a laundering layer that hides the true source of abusive traffic from the party receiving it.
  • Forge headers, spoof addresses, or misrepresent the origin of traffic you send through or from the Service.

The last two matter here more than they would at an ordinary host. Traffic leaving our network carries our addresses. Abuse routed through us lands on our reputation and on every other customer sharing the edge, so we treat it as an attack on the network itself.

4No attack infrastructure

You may not use DEFLECTO to front, protect, accelerate, conceal or provide availability to a service whose purpose, in whole or in part, is attacking other people. This includes:

  • Booter, stresser, IP stresser and “network testing” panels that will fire at a target the buyer does not own, whatever the disclaimer on the front page says.
  • Botnet command and control, loader panels, and the sale or rental of attack capacity.
  • Marketplaces, forums, storefronts or payment pages selling attack services, and the API endpoints those services call.
  • Tooling distributed for the purpose of credential stuffing, account takeover, or bypassing bot mitigation on sites the user does not own.
  • Reflection or amplification lists, target lists, and services that resolve or deanonymise a target's origin address for the purpose of attacking it.

A checkbox saying the user owns the target is not authorisation and will not be treated as one. Neither is a terms page on your own site disclaiming what your product visibly does. We look at what the service is for.

This is stated at length because it is the abuse case a DDoS mitigation provider attracts most, and because the whole value of this network to every other customer depends on it not being here. Accounts found in breach of this clause are terminated, not warned.

5Resource abuse and metering integrity

Billing counts requests we forward to your Origin and never counts traffic we refuse. That rule is deliberately generous and it is therefore worth gaming, so the following are prohibited:

Inflating forwarded counts
Generating traffic through the Service to your own or another party's Protected Property for the purpose of inflating a metered figure, including to exhaust a competitor's quota or to trigger their overage.
Evading the meter
Shaping traffic so that billable requests are recorded as refused, tampering with the counters or the control panel figures, or splitting traffic across accounts to stay under a quota you would otherwise exceed.
Mapping the rule set
Systematically probing the WAF to determine which payloads pass and which are refused, in order to publish those findings, sell an evasion service, or attack another DEFLECTO customer. Tuning rules against your own property with our support team is expected and is not this.
Disproportionate consumption
Consuming edge CPU, memory, connections or bandwidth in a way that degrades the Service for other customers, including deliberately expensive request patterns aimed at the proxy rather than at your application.
Automating around the challenge
Harvesting, sharing, replaying or reselling proof-of-work clearance tokens, or operating a solver farm that mints clearances for clients other than the one that solved the puzzle.

6Security research

We would rather hear about a hole from you than from an attacker. There is a carve out, and it is narrow on purpose.

6.1What is permitted

  • Testing against a Protected Property you own, or one whose owner has given you written permission that you can produce on request.
  • Testing the Service itself at a rate that does not degrade it for anyone else, with no volumetric or denial of service component, and with no attempt to reach another customer's data or configuration.
  • Reporting what you find to us privately and promptly.

6.2What is not

  • Load testing, stress testing or any flood, however it is labelled. If you want to test capacity, arrange it with us in writing first.
  • Accessing, modifying, exfiltrating or retaining another customer's data or traffic. Stop at the point that proves the issue exists.
  • Social engineering our staff, our resellers or our suppliers, and physical attacks on any facility.
  • Publishing, selling or otherwise disclosing a finding before it is fixed, or using a finding to gain an advantage over another customer.
  • Demanding payment as a condition of disclosure.

6.3How to report

Write to support@deflecto.net with SECURITY in the subject line. Include what you did, what you observed, and enough detail to reproduce it. We acknowledge within two working days and will tell you our assessment and our expected fix timeline. Please give us 90 days before any public disclosure, and we will credit you when the fix ships unless you ask us not to.

Research that stays inside 6.1 and follows 6.3 will not lead to action against you under this policy, and we will not pursue a legal claim over it. This is not a paid bug bounty, and it is not a waiver of any third party's rights.

7Reporting abuse

To report a site or an account abusing this policy, write to support@deflecto.net with ABUSE in the subject line. Include the hostname or URL, the behaviour you observed, timestamps with a timezone, and log excerpts or headers if you have them. A report with evidence is actioned quickly. A report that is only an assertion takes longer, because we have to establish the facts ourselves.

We read every report. We do not always tell the reporter what we did, because what we did is usually between us and our customer, but a report about active harm to a network gets a response either way.

Because we are a proxy, our customer is frequently not the author of the content complained about. Where the material sits with a downstream site operator we will pass the report on and, where the law requires it, identify the responsible party to a competent authority.

8Consequences

What we do depends on what is happening and how much harm is in progress. The ladder is:

1. Notice
We contact the account with what we saw and a deadline to fix it, ordinarily 48 hours. Most breaches are a misconfiguration or a compromised customer site and end here.
2. Restriction
We limit the affected Protected Property, tighten the posture on it, or block specific routes, while leaving the rest of the account running.
3. Suspension
The Protected Property or the account stops being answered for. Applied where a notice was not acted on, or where the breach is serious enough that waiting is not reasonable.
4. Termination
The account is closed under clause 9 of the Terms of Service. Fees already paid are not refunded where termination follows a breach of this policy.
Immediate action
We skip straight to suspension or termination, without prior notice, where there is active harm to our network or to a third party, where clause 4 is breached, where the content is CSAM, or where a court or competent authority requires it.

Where the conduct is criminal, or where there is a risk to a person, we will preserve what evidence we hold and report it to the appropriate authority in [[JURISDICTION]] or in the jurisdiction affected.

9Appeals and reinstatement

If you believe we got it wrong, reply to the enforcement notice within 14 days explaining why, with evidence. A different person from the one who made the original decision reviews it, and we aim to answer within five working days. A suspension is lifted if the review finds in your favour or if the underlying issue is fixed and we are satisfied it will not recur.

Terminations under clause 4 or for CSAM are not subject to appeal.

10Changes and contact

We may update this policy as abuse patterns change. Material changes are notified to account holders by email at least 30 days before they take effect, except where a change is needed immediately to address an active threat, in which case it takes effect on publication and is announced at the same time.

Abuse and security: support@deflecto.net. Commercial questions, including reseller agreements: sales@deflecto.net. Registered entity and address: DEFLECTO LLC, [[REGISTERED_ADDRESS]].